﻿using System.Data.SqlClient;
using System.Web.Mvc;
using webcspa.Models;

namespace webcspa.Controllers
{
    public class RegisterController : Controller
    {
        private const string connectionString = "Data Source=GORBUNOV-MS\\GORBUNOV;Initial Catalog=Users;Persist Security Info=True;User ID=sa;Password=vbif0192837465";

        public ActionResult Run()
        {
            ViewData["Message"] = Request.QueryString.Get("Message");
            return View("View", (object)Request.QueryString.Get("Login"));
        }

        [HttpPost]
        public ActionResult Register()
        {
            var form = Request.Form;
            var user = new User
                           {
                               Login = form.Get("Login"),
                               Password = form.Get("Password")
                           };
            if (form.Get("Confirmation") != user.Password)
                return RedirectToAction("Run", new {login = user.Login, message = "Подтверждение пароля не совпадает"});
            using (var connection = new SqlConnection(connectionString))
            {
                connection.Open();
                var command = connection.CreateCommand();
                command.CommandText = string.Format("insert into users values('{0}', '{1}')", user.Login, user.Password);
                command.ExecuteNonQuery();
            }
            return View("View");
        }
    }
}
